Description
Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS 7), Movable Type 6.5.3 and earlier (Movable Type 6.5), Movable Type Advanced 6.5.3 and earlier (Movable Type Advanced 6.5), Movable Type 6.3.11 and earlier (Movable Type 6.3), Movable Type Advanced 6.3.11 and earlier (Movable Type 6.3), Movable Type Premium 1.29 and earlier, and Movable Type Premium Advanced 1.29 and earlier) allow remote authenticated attackers to upload arbitrary files and execute a php script via unspecified vectors.
References (2)
Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://movabletype.org/news/2020/05/mt-730-660-6312-released.html
Third Party Advisory, VDB Entry x_refsource_misc
https://jvn.jp/en/jp/JVN28806943/index.html
Scores
CVSS v3
8.8
EPSS
0.0085
EPSS Percentile
75.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (3)
sixapart/movable_type
< 1.29 (2 CPE variants)
sixapart/movable_type
6.3 - 6.3.11
sixapart/movable_type
7.0 - 7.2.1
Published
May 14, 2020
Tracked Since
Feb 18, 2026